Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.

AI attack

Adversaries, both criminal and state-sponsored, are increasingly using AI to automate and scale their attacks, according to Google’s Threat Intelligence Group (GTIG).

What started as relatively simple adversarial prompt injection into enterprise AI systems has become a full-blown war, with aggressors developing and using their own AI systems, and enterprises using additional AI defenses that provide an expanded attack surface. It is an ongoing and expanding loop that is unlikely to abate.

Google, straddling both sides of this war (partly a cause by developing Gemini, and partly a defense in its efforts to detect and shut down attackers), has chronicled the evolution through 2026.

The overall effect of this automation is an increased speed of attack, and TeamPCP (UNC6780) provides an example. “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” say the Google researchers.

Harnessing AI allows attackers to operate at a scale more typically associated with larger and better resourced groups, such as those affiliated with nation states.

TeamPCP is also used to highlight the growing severity of threat actor exploitation of AI and the open source supply chain. Since March 2026, the actor has conducted such compromises against targets including PyPI, npm, and Docker Hub. It has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices, some of which are embedded within its Dustmaker credential stealer software.

TeamPCP also developed Shai-Hulud and Miasma, both of which are publicly available. GTIG believes “The publicity, apparent success, and open-source release of UNC6780’s malware will likely spur adversary emulation of these tactics.”

Advertisement. Scroll to continue reading.

The group is just one of many actors similarly using AI as a force multiplier for their activities. If a cybersecurity attack is a firefight, AI is fanning the flames. But it’s not just financially motivated criminals taking advantage – nation state actors are also increasingly leaning into AI.

In June 2026, GTIG reported on a multi-year cyberespionage campaign by UNC6508, a People’s Republic of China (PRC)-nexus threat actor, targeting academic, medical, and military research institutions in North America.

GTIG has also identified various nation-state actors keen on developing offensive agentic AI tools. One PRC group has been seen experimenting with AI-powered development tools to build an AI-assisted, automated exploitation and post-exploitation pipeline. 

PRC-nexus Basin Castle has been seen querying LLMs to profile high-value targets during early-stage reconnaissance, draft and translate localized social engineering lures, author obfuscated custom malware, and troubleshoot post-exploitation commands.

Calanque Ion (aka APT42), an Iran-backed group, has used gen-AI (including Gemini) to identify target email addresses, conduct OSINT research, and translate content across local languages to craft localized pretext lures.

Ravine Castle (aka APT24), also PRC-nexus, uses Gemini across the entire attack lifecycle from intelligence gathering to attack capability development, and influence operations. It has also been seen using Gemini to generate politically charged propaganda; research methods on anonymizing data leaks for downstream dissemination to journalists and social media influencers.

Midnight Neptune (UNC1069) is a DPRK-nexus actor that has increasingly integrated AI across its operational lifecycles to support cryptocurrency theft.

Google’s response to this increase in AI-assisted attacks is to disrupt adversarial operations by disabling associated projects and accounts whenever it identifies them. It also hardens its own models against misuse; for example, “In response to model extraction – or ‘distillation’ – attacks, we have deployed real-time defenses designed to degrade the performance of unauthorized ‘student’ models and detect attempts to clone proprietary logic.” (See here for CISA’s details on China’s distillation attacks against US frontier AI companies.)

The basic problem, however, is AI’s facility in finding vulnerabilities and developing new malware and exploits. So long as this persists, bad actors will use AI as a force multiplier for their activities. There will never be a lack of vulnerabilities – as fast as they are located and patched, they are replaced by different vulnerabilities in new software. Good actors such as Google may find and disrupt adversarial activities, but the bad actors will move, adapt and carry on. That has been the pattern in cybersecurity since the internet began – only the details change. AI introduces many more details and adds speed and scale, but the basic warzone is and is likely to remain unchanged.

Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours

Related: Google DeepMind Unveils Framework to Exploit AI’s Cyber Weaknesses

Related: UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election

Related: Cyber Insights 2026: Cyberwar and Rising Nation State Threats

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.